Reporting a vulnerability
If you think you have found a security problem in one of our apps, websites or licence servers, please write to support@mokasolutions.dev with "Security" in the subject. Include what you found, how to reproduce it, and what impact you think it has. You can write in English or Italian.
We will:
- confirm we received your report within 3 working days;
- keep you informed while we investigate and fix it;
- credit you when we publish the fix, if you wish.
Please give us reasonable time to release a fix before disclosing the issue publicly — normally 90 days, or less if we agree on it together.
Good-faith research
We will not take legal action against research carried out in good faith that respects these rules:
- test only against your own devices, accounts and licences;
- don't access, change or delete other people's data, and stop as soon as you reach any;
- don't degrade our services (no denial-of-service or high-volume automated testing), and don't use social engineering or physical attacks;
- don't publish or share licence keys, and don't use a vulnerability beyond what is needed to show it.
We don't run a paid bug bounty, but we are two people who genuinely appreciate the help.
A machine-readable version of this policy is at /.well-known/security.txt.